US10320808B2ActiveUtilityA1

Clickjacking prevention

Assignee: CERNER INNOVATION INCPriority: Oct 25, 2016Filed: Oct 25, 2016Granted: Jun 11, 2019
Est. expiryOct 25, 2036(~10.3 yrs left)· nominal 20-yr term from priority
H04L 63/0876G06F 21/563G06F 21/316G06F 21/31H04L 63/1441G06F 21/51H04L 67/02H04L 63/123H04L 63/1466
25
PatentIndex Score
0
Cited by
18
References
20
Claims

Abstract

Systems and methods provide for clickjacking prevention code provided in an embedded webpage to prevent clickjacking when the embedded webpage is called by an embedding webpage determined to be illegitimate. When the embedded webpage is loaded on a user device, the clickjacking prevention code is executed and initially prevents content of the embedded webpage from being rendered. Additionally, the clickjacking prevention code sends a message containing a secret to a known domain that provides legitimate embedding webpages. When the embedding webpage sends a message to the embedded webpage, the message is checked to see if it contains the secret. If the message contains the secret, the embedding webpage is legitimate since it originated from the known domain, and the content of the embedded webpage is rendered. Alternatively, if the message does not contain the secret, the content of the webpage is not rendered.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
       1. One or more non-transitory computer storage media storing computer-useable instructions that, when executed by a computing device, cause the computing device to perform operations, the operations comprising:
 preventing content of an embedded webpage from being rendered on a user device, the embedded webpage having been called by an embedding webpage; 
 sending a message containing a secret from the embedding webpage on the user device to a server of a known domain; 
 after sending the message containing the secret to the server, receiving a message from the embedding webpage that called the embedded webpage; 
 determining, on the user device, whether the message from the embedding webpage includes the secret, the message from the embedding webpage including the secret when the embedding webpage is legitimate and receives the secret from the server after the secret is sent to the server from the user device; 
 when the message from the embedding webpage includes the secret, allowing the content of the embedded webpage to be rendered; and 
 when the message from the embedding webpage does not include the secret, continuing to prevent the content of the embedded webpage from being rendered. 
 
     
     
       2. The one or more computer storage media of  claim 1 , wherein the content of the embedded webpage is prevented from being rendered using a framekiller technique. 
     
     
       3. The one or more computer storage media of  claim 1 , wherein the message to the known domain is a PostMessage. 
     
     
       4. The one or more computer storage media of  claim 1 , wherein the message from the embedding webpage is a PostMessage. 
     
     
       5. The one or more computer storage media of  claim 1 , wherein the embedding webpage calls the embedded webpage to be displayed within an iframe. 
     
     
       6. The one or more computer storage media of  claim 1 , wherein the operations are performed by a web browser on the user device. 
     
     
       7. The one or more computer storage media of  claim 1 , wherein the operations further comprise sending a message containing the secret to at least one other known domain. 
     
     
       8. A computer-implemented method for preventing clickjacking on a user device, the method comprising:
 receiving an embedded webpage called by an embedding webpage rendered on the user device, the embedded webpage containing clickjacking prevention code; and 
 executing the clickjacking prevention code on the user device to perform operations that include:
 preventing content of the embedded webpage from being rendered; 
 sending a message containing a secret to a server of a known domain; 
 after sending the message containing the secret to the server, receiving a message from the embedding webpage that called the embedded webpage; 
 determining whether the message from the embedding webpage includes the secret, the message from the embedding webpage including the secret when the embedding webpage is legitimate and receives the secret from the server after the secret is sent to the server from the user device; 
 when the message from the embedding webpage includes the secret, allowing the content of the embedded webpage to be rendered; and 
 when the message from the embedding webpage does not include the secret, continuing to prevent the content of the embedded webpage from being rendered. 
 
 
     
     
       9. The method of  claim 8 , wherein the content of the embedded webpage is prevented from being rendered using a framekiller technique. 
     
     
       10. The method of  claim 8 , wherein the message to the known domain is a PostMessage. 
     
     
       11. The method of  claim 8 , wherein the message from the embedding webpage is a PostMessage. 
     
     
       12. The method of  claim 8 , wherein the embedding webpage calls the embedded webpage to be displayed within an iframe. 
     
     
       13. The method of  claim 8 , wherein the method is performed by a web browser on the user device. 
     
     
       14. The method of  claim 8 , wherein the method further comprises sending a message containing the secret to at least one other known domain. 
     
     
       15. A computer system comprising:
 one or more hardware processors; and 
 one or more computer storage media storing computer-useable instructions that, when used by the one or more processors, cause the one or more processors to: 
 receive a request for an embedded webpage from a user device, the request having been generated in response to an embedding webpage calling the embedded webpage; and 
 providing the embedded webpage in response to the request, the embedded webpage including clickjacking prevention code that when executed on the client device causes the client device to perform operations that include:
 preventing content of the embedded webpage from being rendered; 
 sending a message containing a secret to a server of a known domain; 
 after sending the message containing the secret to the server, receiving a message from the embedding webpage that called the embedded webpage; 
 determining whether the message from the embedding webpage includes the secret, the message from the embedding webpage including the secret when the embedding webpage is legitimate and receives the secret from the server after the secret is sent to the server from the user device; 
 when the message from the embedding webpage includes the secret, allowing the content of the embedded webpage to be rendered; and 
 when the message from the embedding webpage does not include the secret, continuing to prevent the content of the embedded webpage from being rendered. 
 
 
     
     
       16. The system of  claim 15 , wherein the content of the embedded webpage is prevented from being rendered using a framekiller technique. 
     
     
       17. The system of  claim 15 , wherein the message to the known domain is a PostMessage. 
     
     
       18. The system of  claim 15 , wherein the message from the embedding webpage is a PostMessage. 
     
     
       19. The system of  claim 15 , wherein the embedding webpage calls the embedded webpage to be displayed within an iframe. 
     
     
       20. The system of  claim 15 , wherein the operations further comprise sending a message containing the secret to at least one other known domain.

Join the waitlist — get patent alerts

Track US10320808B2 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.